← Back

CVE-2023-36611

nvd nist
Published: Jul 3, 2023Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

The affected TBox RTUs allow low privilege users to access software security tokens of higher privilege. This could allow an attacker with “user” privileges to access files requiring higher privileges by establishing an SSH session and providing the other tokens.

Affected (5)

5 products
Tbox Ms Cpu32 Firmware
Tbox Ms Cpu32 S2 Firmware
Tbox Lt2 Firmware
Tbox Tg2 Firmware
Tbox Rm2 Firmware
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.50.598
Running on/withPlatform Versions
Ovarro
Tbox Ms Cpu32
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.50.598
Running on/withPlatform Versions
Ovarro
Tbox Ms Cpu32 S2
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.50.598
Running on/withPlatform Versions
Ovarro
Tbox Lt2
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.50.598
Running on/withPlatform Versions
Ovarro
Tbox Tg2
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 1.50.598
Running on/withPlatform Versions
Ovarro
Tbox Rm2
All versions

References (2)

Source: ics-cert@hq.dhs.gov
MitigationThird Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government Resource

Timeline

No history available yet.